IMPLEMENTAUDIT
On this page
  1. Contributor contract
  2. Review order
  3. Public capability projection
  4. Maintenance surfaces
  5. Sidecar boundary
  6. Plugin cache warning
  7. Source surfaces
Audience

For auditors and maintainers

Use this path to find the current contributor contract and to review whether a run, public claim, package boundary, or release record is truthful to evidence.

Contributor contract

CONTRIBUTING.md is the current owner for repository workflow: instruction precedence, canonical and generated owners, supported shell paths, validation order, helper reachability, package boundaries, evidence destinations, and separately authorised Git/GitHub mutations.

Use this portal page as a route and review aid, not as a second copy of that contract. Runtime behaviour remains owned by the packaged skill sources, release chronology by CHANGELOG.md, and exact publication evidence by the applicable release report.

Review order

  1. Read the request, governing AGENTS.md files, CONTRIBUTING.md, and the bound work record; for phased work, inspect the run folder, STATE.md, roadmap, phase specs, and failure rows.
  2. Compare before/after evidence and repo-state output.
  3. Verify marker order: AUDIT_COMPLETE before IMPLEMENTAUDIT_RUN_COMPLETE.
  4. At release gates, verify scripts/check-public-claim-boundaries.sh ran with forbidden identity terms supplied at runtime and recorded PASS/FAIL without writing those terms into tracked files.
  5. Reject overclaims about install proof, host load, publication, provenance, sidecar proof, or package contents.
  6. For public- or release-facing work, challenge unsupported claims, omitted material capabilities, stale routes, competing authorities, and content placed for the wrong audience or abstraction level.

Public capability projection

Activate only when all three hold: a material public/release effect; README or public docs are declared success carriers; and the run intends a current, complete, or release-final claim.
Otherwise create no projection record. Derive the topic population from authoritative owners; do not search only for familiar stale strings.

Record population_definition, population_size, examined_count, and enumeration_source, plus a discrimination witness when distinct owners could collapse to one copied pointer.
For each topic record owner/source, README disposition, docs disposition, current-state transition, and evidence.

Allowed dispositions are present-correct, discoverably-delegated, historical-intentional, not-user-facing, and missing.
Allowed transitions are not-applicable, prepublication-current, postpublication-current, and stale.

A concise maintained delegation is valid and factual parity does not require duplicated wording.
A partial sample stays partial; generated output is repaired through its owner; postpublication state needs fresh semantic readback; and an existing claim-boundary failure still fails.

Maintenance surfaces

Sidecar boundary

These sidecars may be required for explicitly configured dogfood maintenance, but they remain optional for consuming repos.
Graphify is qualified first-contact orientation after the executable SHA freshness check.
ActiveGraph is fork/diff checkpoint assistance or an optional non-authoritative mirror; the run root remains lifecycle authority.

Plugin cache warning

Claude plugin cache refresh depends on a version-field change.
Shipped code changes need a version bump before claiming update behavior; that warning is not a release or install claim.

Source surfaces

Use AGENTS.md for the concise repository bootloader, CONTRIBUTING.md for the current contributor contract, README.md for new-user orientation, skills/implementaudit/references/audit-playbook.md for the packaged public-projection method, docs/audits/ for evidence custody, and the validation owners for executable checks.